Scope and purpose
This policy is applicable to the Processing of customers' Personal Data at all companies included in the Polestar Group ("Polestar," "our," "us," or "we"). The purpose of this policy is to provide our current, former and potential customers (jointly referred to as "customers" or "you") with a general understanding of:
- •The circumstances under which we collect and process your Personal Data
- •The types of Personal Data we collect
- •The reasons for collecting your Personal Data
- •How we handle your Personal Data
- •Distribution of responsibility for the Processing of Personal Data between various legal entities at Polestar, and
- •Our contact details so you can receive information about and claim your rights in relation to our Processing of your Personal Data.
This policy is updated continuously to reflect the measures taken by Polestar in relation to your Personal Data.
Polestar Performance AB (a Swedish legal entity with corporate registration number 556653-3096) is the Controller in relation to the Processing of your Personal Data for research and development of new and current car models, and also for certain global services offered to customers. Furthermore, Polestar Performance AB is the Controller for any Processing of Personal Data in relation to the monitoring of car quality and any potential safety recalls, as well as to meet regulatory requirements.
Each national sales company within Polestar is generally responsible for marketing, sales, and customer relations, as well as market-specific services in its market. The national sales company is the Controller for the Processing of Personal Data for these purposes. In markets without a national sales company, an importer usually has the same responsibility as a national sales company. Therefore, the importer is the Controller in these instances.
Principles of data Processing
The Processing of your Personal Data forms an important part of our provision of products and services to you. We appreciate the trust you place in us when providing us with your Personal Data and consider your privacy an essential part of the services we offer. In order to safeguard your personal data while increasing customer value and offering enhanced and safer driving experiences, we adhere to the following five general principles.
Freedom of choice
Your personal data belongs to you. We strive not to make any assumptions regarding your privacy preferences and aim to design our services so that you can choose whether to share your personal data with us.
Balance of interests
Where the Processing of your Personal Data is necessary for the pursuit of a legitimate interest, and where this interest outweighs the need to protect your privacy, we may process certain Personal Data without obtaining your consent if so permitted by law. In certain other situations, we may also process your Personal Data without your consent if it is so required in accordance with applicable law. For more information, see the "Consent" section below.
Polestar will only process our customers' Personal Data if it is adequate, relevant, and necessary in relation to the purpose for which it has been gathered. We aim to anonymize your personal data when a function or service can be achieved with anonymized data. If we combine anonymized or non-personal data with your personal data, it will be treated as personal data for as long as it remains combined.
Transparency and security
Polestar believes in being transparent about which Personal Data we process and for which purposes. On request, Polestar will provide customers with further information regarding our Processing and protection of your Personal Data.
Polestar's policy is to comply with the applicable laws, rules, and regulations governing privacy and data protection in each and every country where we operate. Where necessary, we will adjust our processing of your personal data as described in this policy to ensure legal compliance.
The Personal Data collected by Polestar about you and the vehicle will be used:
- •to provide you with products and services, including to verify your eligibility for certain purchases and services, as well as to offer you enhanced offers and experiences;
- •to inform you of updates to, or changes in, our products and services, including but not limited to changes to our terms and conditions and policies;
- •to inform you of new products, services, and events;
- •to provide vehicle support and services (warranty service, recall information, etc.);
- •for product development purposes: for example, to improve vehicle performance, quality, and safety;
- •to evaluate and improve our offerings to and communication with customers;
- •to comply with legal requirements or lawful requests from the authorities;
- •to inform you about our products and services and identify those that may be of interest to you;
- •to carry out market research; and
- •for analysis and customer profiling purposes (online and social media included) done by ourselves and our chosen suppliers.
The following definitions are used in this policy:
- •"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data;
- •"Processor" means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller;
- •"Personal Data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is someone who can be directly or indirectly identified: in particular, by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
- •"Processing" means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, or destruction;
- •"Sensitive Personal Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the Processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
You may provide us with information about you or your vehicle when utilizing Polestar's services in or outside a vehicle or in other contacts with Polestar: for example, through our websites or customer centers (in this context, please note that phone calls may be recorded for quality assurance purposes, with your consent). We may also obtain such data from our repairers and other third parties. Such data may include:
- •your contact information (name, address, telephone number, email address, etc.);
- •demographic information (age, marital status, household composition, etc.);
- •vehicle information (vehicle identification number [VIN], model, date of purchase, service history, etc.);
- •location data generated by your activities (navigation assistance, search queries, location sharing, etc.); and
- •data pertaining to your purchase and use of our products and services (customer preferences and settings, purchase history, Polestar ID, etc.).
Your vehicle will also automatically collect data relating to the vehicle and its surroundings, primarily of a technical nature and not directly related to you as a person. Such data ("Vehicle-Recorded Data") is typically connected to the vehicle identification number (VIN) of the vehicle and may therefore be traceable to you. Vehicle-Recorded Data may include:
- •safety information (whether airbags or belt tensioners have been triggered, whether the doors and windows are locked or open, etc.);
- •system functionality status (of the battery, engine, throttle, steering, and brakes, etc.);
- •driving data (vehicle speed, brake and accelerator pedal use, steering wheel movement, etc.);
- •location data (the position of the vehicle in case of an accident, etc.); and
- •data on the surroundings (temperature outside the vehicle, images, etc.).
Information about certain Vehicle-Recorded Data is also included in the Owner's Manual.
We are particularly careful and apply additional measures if and when collecting and processing sensitive personal data, as required by applicable law. To avoid doubt, it is noted that applicable law may require other kinds of data to also be treated as Sensitive Personal Data.
Where reasonably practical or as required by applicable law, we will, in connection with collecting or registering your Personal Data, provide you with (i) specific information regarding the purposes of the Processing of your Personal Data, (ii) the identity of the Controller, (iii) the identities of any third parties to whom the data may be disclosed, and (iv) other information which may be necessary to ensure that you are able to safeguard your rights. The above information may, for example, be provided when you purchase a vehicle, in the vehicle's infotainment system, in mobile applications developed by Polestar, at https://www.polestar.com or otherwise in an agreement entered into between you and Polestar.
Where reasonably practical or as required by applicable law, we will obtain your consent prior to collecting or using your personal data. The request for your consent will be clear and specific and will provide you with a reasonable basis on which to make your decision. We will never take your consent for granted and will make sure that you can provide your consent in a clear and transparent manner. Your consent is voluntary and may always be revoked: for example, by terminating a particular service or contacting Polestar at the address indicated in the "Information and access" section below. Please note that where your consent is required and you do not give your consent, it may not be possible for you to use certain services or parts of such services.
Collection and Processing of Personal Data without consent
The collection and use of Vehicle-Recorded Data may be necessary in order for (i) technicians to diagnose and rectify faults in vehicles during the service and maintenance of vehicles, (ii) Polestar's product development: for example, enhancements of the vehicles' quality and safety features, (iii) managing Polestar's warranty undertakings and (iv) fulfillment of legal requirements. When collecting or using Vehicle-Recorded Data for these purposes, and for similar legitimate interests pursued by Polestar, we will generally not seek your consent unless this is deemed necessary in the individual case or is required by applicable law.
Third party applications
You may access certain applications and other services linked with the vehicle but provided by a third party which may, for example, require transmission of location data and other Vehicle-Recorded Data to such third party. Polestar is not responsible for the collection or use of Personal Data in applications or services provided by third parties and recommends that you carefully review applicable terms for (and any integrity policy related to) such applications or services before you use them. If you have questions concerning a certain third party's use of your Personal Data, please contact the third party directly.
Polestar may transfer your Personal Data to recipients in countries outside of the European Economic Area that may have differing data protection laws. This includes countries which the EU Commission does not consider to have an adequate level of protection for Personal Data. If this occurs, Polestar will ensure there is a legal ground for the transfer in accordance with applicable data protection legislation. You will also be informed about the legal ground, what safeguards were implemented, and where you can obtain a copy of information on these safeguards.
For most Processing acts, you are able to terminate our use of your Personal Data by updating your preferences, terminating a particular service, revoking your consent to the Processing by contacting Polestar at the address indicated in the "Information and access" section below, or as otherwise instructed by us. However, and unless otherwise follows from applicable law, you may generally not opt out of the Processing of your Personal Data:
- •in relation to certain acts of collection and further Processing of your Vehicle-Recorded Data relating to safety, quality, and product improvement;
- •which we perform in order to send you important notices, such as changes to our terms and conditions and policies or in the event of product recalls; and
- •which we perform in order to comply with our legal obligations.
We will only retain your Personal Data for as long as it is necessary to fulfill the purposes outlined in this policy or the purposes of which you have otherwise been informed. This means that when you have consented to our Processing of your Personal Data, we will retain the data for as long as the customer relationship lasts (and, where applicable, until the expiration of the warranty period) or until you withdraw your consent. If you have revoked your consent, we may nevertheless retain certain Personal Data for the period required in order for us to meet our legal obligations and defend ourselves in legal disputes. If we have not received your consent for Processing, the Personal Data will only be retained to the extent we are permitted to do so by law.
We strive to ensure that your Personal Data is correct and up to date when Processing it. We attempt to delete or correct Personal Data that is incorrect or incomplete. For more information regarding your right to ensure the accuracy of your Personal Data kept by us, please see the "Information and access" section below.
Information and access
As stated in the "Notice" section above, we may provide you with specific information concerning our processing of your personal data when collecting or recording such data. You have the right to request (i) a copy of the Personal Data that we store about you (ii) that we correct or remove Personal Data that you think is inaccurate, and (iii) to have your Personal Data deleted and to have our processing of your Personal Data restricted in certain circumstances. In addition, you have the right to object to our Processing of your Personal Data, as well as to receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format and to have these transmitted to another Controller.
Requests should be sent to the legal entity set out at the end of this document. Your requests will be dealt with in a prompt and proper manner. Where applicable law provides for an administrative fee for complying with your request(s), such fee may be charged by Polestar. In addition, you may be able to access an overview of certain Personal Data that you have provided directly and that is held by Polestar, and correct or update your information, by logging into the Polestar consumer portal account or a similar service offered in your local market. For more information on your rights, please contact our Data Protection Officer. Please see contact details for our Data Protection Officer at the end of this document.
Polestar has taken technical and organizational measures in order to protect your Personal Data against accidental or unlawful destruction, accidental loss or alteration, unauthorized disclosure or access, and any other unlawful forms of Processing.
Disclosures to third parties
Polestar may share your Personal Data:
- •among Polestar units;
- •with Polestar's repairers for the purpose of distributing product and service offers and other communications to you; with other business partners for the purpose of distributing product and service offers and other communications to you, or for research and development purposes;
- •in connection with the sale or transfer of a Polestar entity or its assets;
- •as required by law: for example, in connection with a government inquiry, dispute, or other legal process or request;
- •when we, in good faith, believe that disclosure is necessary in order to protect our rights: for example, in order to investigate potential violations of our terms and conditions or to detect, prevent, or disclose fraud or other security issues
- •with other business partners or third parties where you have elected to receive a service from them and authorized them to request data from Polestar (for example, for Polestar In-car Delivery);
- •with our product and service providers who work on our behalf in connection with the above uses, such as wireless service providers, companies that host or operate our website, send communications, perform data analytics, credit card processors, or system providers necessary to process, store, or manage credit card or financial information; and
- •with emergency services providers, such as law enforcement, roadside assistance providers, and ambulance providers, in order to deliver related services (for example, for On Call Emergency Support).
A Polestar entity, as the Controller of your Personal Data, will, as a general rule, only disclose your Personal Data to a third party if it has received your consent to do so. However, if permitted by law we may share your Personal Data without your consent, unless we consider your consent necessary in the individual case or your consent is required by law, in the following situations:
- •when disclosure is required by law; and
- •when disclosure is necessary for the purpose of a legitimate interest pursued by Polestar (for example, in order to protect our legal rights, as described above).
Data Processing on our behalf
We restrict access to your Personal Data to Polestar's employees and suppliers who need to use the information in order to process it on our behalf and who are contractually required to keep your Personal Data secure and confidential. We aim to choose the option for Processing services that best safeguards the integrity of your Personal Data with respect to any third party. Some of these Processing activities might be performed outside of the EEA under a specific legal basis, as required by national law.
We will not sell or trade your Personal Data with third parties unless we have your consent to do so. We will not share your Personal Data with third parties for their marketing purposes unless we have received your consent for such disclosures. If you have provided such consent but wish to stop receiving marketing materials from a third party, please contact that third party directly. We may provide you with information regarding new products, services, events, or similar marketing activities. If you wish to unsubscribe from a particular e-mail newsletter or similar communication, please follow the instructions in the relevant communication.
Websites and cookies
When you download or register to use one of our apps, you may submit Personal Data to us, such as your name, email address, phone number, and other registration information. Furthermore, when you use our apps, we may collect certain information automatically, including technical information related to your mobile device and information about the way you use the app. Depending on the particular app you use and only after you have consented to such collection, we may also collect information stored on your device, including contact information, location information, or other digital content. Further details about the kind of information we collect is set out in the information notice and/or the special notice for each individual app.
Third-party services and apps
Our services are not intended for use by children. We do not knowingly solicit or collect any Personal Data about children under the age of 13 or market our products or services to them. If a child has provided us with Personal Data, a parent or guardian of that child may contact us to have the information deleted from our records. If you believe that we might have any information from a child under age 13, please contact us. If we learn that we have inadvertently collected the personal information of a child under 13, or equivalent minimum age depending on jurisdiction, we will take steps to delete the information as soon as possible.
As a result of legal requirements, we have to monitor how our system works, including the vehicles we have produced. This means that we collect sample data from these vehicles.
Lodging of complaints with the supervisory authority
If you are of the opinion that we are Processing your Personal Data in violation of data protection laws and regulations, you have the right to lodge a complaint with your supervisory authority.
To exercise your rights as a data subject, e.g. to obtain information in regards to Polestar's Processing of your Personal Data or to access Personal Data that Polestar processes in relation to you, please use this WEB FORM.
Data Protection Officer
Polestar has appointed a Data Protection Officer for the Group who can be reached via e-mail or via post as set out below:
E-mail address: email@example.com
Mailing address: Polestar Performance AB, Attention: The Data Protection Officer, 405 31 Göteborg, Sweden.